MALICIOUS — 8691040.pdf
MALICIOUS — 8691040.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
55dccf9d8e99588d5156a2c8c3f3623b559c131c521280d0d58e11b458edf70b - SHA-1:
903231974140616f371bfb77aa32608f8ab37d68 - MD5:
9e1f56ab3b31d09beeee075f613236b3 - ssdeep:
1536:W6T17CtrNK1DcZjmMN42jU3ZUe8ovFifsmdCBAz8fc9Ox:3x7CxN7jmMJjQCeHiFCBAzYca - TLSH:
T1D837CFF36197DF8C7BC31B03B8A218953486DB9950329A54188CB6BDD1BC6FE6D00E52 - Submitted as: 8691040.pdf
- File type: pdf · Size: 69695 bytes
- Verdict: malicious (94/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://saxibodusazo.weebly.com/uploads/1/3/0/7/130740440/sulub.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://trafffi.ru/wb?keyword=the%20crimson%20ghost%201946%20dvd, https://fenorave.weebly.com/uploads/1/3/4/6/134639489/9872364.pdf, https://duxakezise.weebly.com/uploads/1/3/4/7/134713437/3528690.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafffi.ru/wb?keyword=the%20crimson%20ghost%201946%20dvd
- https://fenorave.weebly.com/uploads/1/3/4/6/134639489/9872364.pdf
- https://s3.amazonaws.com/tojabixefova/elf_last_names_5e.pdf
- https://duxakezise.weebly.com/uploads/1/3/4/7/134713437/3528690.pdf
- https://gijepeparo.weebly.com/uploads/1/3/4/3/134318767/7331319.pdf
- https://uploads.strikinglycdn.com/files/070b35ee-e5e5-4277-9f11-ac646e89dd77/thunder_breaker_skill_guide_maplestory_m.pdf
- https://uploads.strikinglycdn.com/files/ed1c007d-cf72-4444-a0f7-2d1d745f40d5/temple_of_ascending_flame_lilith.pdf
- https://naxesitigas.weebly.com/uploads/1/3/0/7/130740165/9b773f32ab.pdf
- https://uploads.strikinglycdn.com/files/6783c56c-11e6-4458-9baa-746df03c3226/kamobodumizelexemuleboz.pdf
- https://saxibodusazo.weebly.com/uploads/1/3/0/7/130740440/sulub.pdf
- https://uploads.strikinglycdn.com/files/b04c9582-3029-44fe-b479-99c18875ed59/solawozuxudosadabudike.pdf
- https://uploads.strikinglycdn.com/files/94d8cfd7-03b3-4856-83a6-e669585c100a/60118906631.pdf
- https://sopizelofixafav.weebly.com/uploads/1/3/4/4/134438569/valas-posasaliriloro.pdf
- https://zovotinaselon.weebly.com/uploads/1/3/4/5/134589175/fumulowatame.pdf
- https://nexajatolotol.weebly.com/uploads/1/3/4/3/134308242/8234722.pdf
- https://uploads.strikinglycdn.com/files/6d90fa0c-d88a-4faa-beee-8d270bcfcd8b/jine_mera_dil_lutiya_mp3.pdf
- https://zirufifun.weebly.com/uploads/1/3/0/8/130874679/rixefarapuran_luwezixijus_ranopun.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafffi.ru
- fenorave.weebly.com
- s3.amazonaws.com
- duxakezise.weebly.com
- gijepeparo.weebly.com
- uploads.strikinglycdn.com
- naxesitigas.weebly.com
- saxibodusazo.weebly.com
- sopizelofixafav.weebly.com
- zovotinaselon.weebly.com
- nexajatolotol.weebly.com
- zirufifun.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report